Knowledge Management

KVstore field Aliase

florianhh
Explorer

Gooood Morning 🙂

I need some advice, we have several sources of Information about our Company assets, i know not ideal but better then dont know any.

So i wrote a script thats collects everything from these Asset sources and writes the Info to a big KV Store. (1.5GB) on the Splunk-ES SH.

The script does that every 6h. 

No i want to add these Info to the Splunk ES Asset- und Identitäts-Management.

How do i aliase a kvstore field name so its CIM compliance with the required fieldnames as stated here. https://docs.splunk.com/ ?

I thought about fieldaliases in a props.conf as per normal datasources.

But im not sure to use the collection name as a source in the stanza? 

 

 

 

[source::ipam_assets_collection]
FIELDALIAS-asset_ip = Address AS ip

 

 

 

 
Is there a better way?
Labels (3)
0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...